CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012  affected users, the sensitivity level of the information that is concentrated, stored, transmitted or processed on these infrastructures, etc. check the criteria with the development of scenarios that consider the disruption of operation of selected infrastructure, within the bounds of regular exercises. Action 7 - Phase A – Identification and assessment of the critical information infrastructures in the republic of Cyprus, to better target activities and actions for their protection, with the contribution of both the public and private sectors. 3.7 Threat Landscape Analysis Section 2.4 mentioned the general threats that can manifest in cyberspace. It is important to note that available information on the specific mix of threats that appear in Cyprus and which can rise in the future is limited. The protection of information infrastructures can be achieved through general measures only (to some extent), but the strategic response to threats in cyberspace will be greatly improved if the main threats that are actually present and manifest in Cyprus become known. This will not only allow better targeting of response measures, but also better targeting of the most prevalent threats if the necessary protective controls are put in place gradually through a feasible implementation programme for the provisions of this Strategy. A comprehensive threat landscape and attack analysis is therefore necessary (including attacks that are widespread in Cyprus and other European countries), so that the improved targeting of response methods can be achieved, as discussed above. This analysis will be combined with the most prevalent threats that are discussed in European and other international reports for a more complete and comprehensive review. Action 8 - Phase B – Comprehensive survey to record current threats and attacks in cyberspace that have been published in Cyprus, as well as monitoring new threats that appear in the European and international space. 3.8 National Cybersecurity Framework The easiest and most effective method to achieve an acceptable level of security in all critical information infrastructures in the Republic of Cyprus is to develop a National Cybersecurity Framework, which will be used as the basis for the protection of critical information infrastructures, and for information assurance. This framework must be developed based on international security standards and include the following (among others): 21

Select target paragraph3